Description
Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Warehouse Management. While the vulnerability is in Oracle Warehouse Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Warehouse Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Oracle Warehouse Management component Internal Operations and allows an attacker with low privileges to read any data accessible through the HTTPS interface. The CVSS vector (AV:N/AC:L/PR:L/S:C/C:H) indicates a confidentiality‑only impact, which strongly suggests an improper access‑control weakness. The flaw enables information disclosure of all warehouse data to the attacker, potentially exposing sensitive business information.

Affected Systems

The affected product is Oracle Warehouse Management, part of Oracle E‑Business Suite, targeting the Internal Operations component. Versions 12.2.3 through 12.2.15 are vulnerable. The product is accessed over HTTPS, requiring only network access and no elevated user rights.

Risk and Exploitability

The CVSS 3.1 base score of 7.7 reflects high severity for confidentiality, while the EPSS score of less than 1 % indicates that exploitation is considered unlikely but not impossible. The issue is not listed in the CISA KEV catalog. The likely attack vector involves an attacker with network visibility to the Warehouse Management HTTPS endpoint; because the required privileges are low, the vulnerability is deemed easily actionable for an internal or remotely accessed attacker. The Scope component (S:C) signals that a successful exploit may also affect other Oracle E‑BusinessSuite products.

Generated by OpenCVE AI on August 21, 2026 at 08:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch that addresses CVE‑2026‑70771
  • Restrict inbound and outbound HTTPS traffic to the Warehouse Management service to trusted IP ranges and enforce strict role‑based permissions for all users
  • Monitor access logs for anomalous read activity and audit user privileges to ensure only authorized personnel can access warehouse data

Generated by OpenCVE AI on August 21, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access Vulnerability in Oracle Warehouse Management
Weaknesses CWE-284

Fri, 21 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Oracle Warehouse Management Unauthorized Data Access via HTTPS
Weaknesses CWE-284

Wed, 19 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Oracle Warehouse Management Unauthorized Data Access via HTTPS
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Warehouse Management. While the vulnerability is in Oracle Warehouse Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Warehouse Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle warehouse Management
CPEs cpe:2.3:a:oracle:warehouse_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle warehouse Management
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Warehouse Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:24:03.956Z

Reserved: 2026-08-04T22:06:34.596Z

Link: CVE-2026-70771

cve-icon Vulnrichment

Updated: 2026-08-24T14:08:08.403Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:29.893

Modified: 2026-08-28T18:27:02.563

Link: CVE-2026-70771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T08:30:04Z

Weaknesses